IP Library › Granted Patent US 11,556,617
Granted Patent B2
US 11,556,617 · App. 17/861,079 · Granted Jan 17, 2023

Authentication translation

Inventor: Bjorn Markus Jakobsson (Portola Valley, CA)
Assignee: RightQuestion, LLC
G06F21/10G06F21/121G06F21/128G06F21/31G06F21/32G06F21/44H04L63/08H04L63/083H04L63/0815H04L63/0823H04L63/0861H04L63/10H04L63/20H04L63/0281H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,556,617
App. No.
17/861,079
Granted
Jan 17, 2023
Kind
B2
Abstract

Authentication translation is disclosed. A request to access a resource is received at an authentication translator, as is an authentication input. The authentication input corresponds to at least one stored record. The stored record is associated at least with the resource. In response to the receiving, a previously stored credential associated with the resource is accessed. The credential is provided to the resource.

Claims (42)

1. A system, comprising:

one or more processors configured to:

receive, at a first device, a request to access a resource external to the first device, wherein the resource external to the first device is associated with a user;

access at least one record stored on the first device, the at least one record including authentication information associated with the user and credential information associated with the external resource to which the user has requested access, wherein the credential information comprises a cryptographic key;

receive authentication input from the user;

determine that the authentication input from the user matches the authentication information associated with the user included in the at least one record stored on the first device;

retrieve at least a portion of the credential information from the at least one record is stored on the first device;

facilitate access of the user to the external resource at least in part by transmitting, on behalf of the user, from the first device, output based at least in part on the at least portion of the credential information retrieved from the at least one record, wherein the user of the first device is granted access to the external resource based at least in part on the output transmitted from the first device on behalf of the user; and

based at least in part on the first device and a second device being in a shared MAC address range, initiate a backup, to the second device, of at least a portion of the at least one record; and

a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2. The system of claim 1 , wherein the second device is used to authenticate the user to one or more external resources.

3. The system of claim 1 , wherein the backup is completed after the first device has performed a verification that the second device conforms to a policy associated with the at least one record stored on the first device.

4. The system of claim 1 , wherein the backup is completed after a secure channel is established by at least one of the first device and the second device.

5. The system of claim 1 , wherein the first device and the second device are configured to complete a pairing process.

6. The system of claim 5 , wherein the pairing process comprises a comparison of data generated from one or more authentication inputs.

7. The system of claim 1 , wherein subsequent to completion of the backup, the second device comprises a first profile associated with the user of the first device, and a second profile associated with a second user different from the user of the first device.

8. The system of claim 1 , wherein the one or more processors are further configured to:

determine that the authentication input from the user does not match authentication information of a first profile; and

subsequent to determining that the authentication input from the user does not match the is authentication information of the first profile, determine that the authentication input from the user matches authentication information of a second profile, wherein the first profile is associated with a different user than the second profile.

9. The system of claim 1 , wherein the at least one record stored on the first device is stored in a secure storage, and wherein the one or more processors are configured to access the record stored on the secure storage using a restricted interface.

10. The system of claim 9 , wherein the restricted interface comprises a dedicated physical connection.

11. The system of claim 9 , wherein the restricted interface comprises an application programming interface.

12. The system of claim 1 , wherein the backup causes a certificate to be transmitted to the second device.

13. The system of claim 12 , wherein the certificate is generated at least in part by the first device.

14. The system of claim 1 , wherein the authentication input from the user is received using a biometric user input element.

15. The system of claim 1 , wherein the backup comprises copying a modified version of a vault to the second device.

16. A method, comprising:

receiving, at a first device, a request to access a resource external to the first device, wherein the resource external to the first device is associated with a user;

accessing at least one record stored on the first device, the at least one record including authentication information associated with the user and credential information associated with the external resource to which the user has requested access, wherein the credential information comprises a cryptographic key;

receiving authentication input from the user;

determining that the authentication input from the user matches the authentication information associated with the user included in the at least one record stored on the first device;

retrieving at least a portion of the credential information from the at least one record stored on the first device;

facilitating access of the user to the external resource at least in part by transmitting, on behalf of the user, from the first device, output based at least in part on the at least portion of the credential information retrieved from the at least one record, wherein the user of the first device is granted access to the external resource based at least in part on the output transmitted from the first device on behalf of the user; and

based at least in part on the first device and a second device being in a shared MAC address range, initiating a backup, to the second device, of at least a portion of the at least one record.

17. A computer program product embodied in a non-transitory computer readable storage medium and comprising computing instructions for:

receiving, at a first device, a request to access a resource external to the first device, wherein the resource external to the first device is associated with a user;

accessing at least one record stored on the first device, the at least one record including authentication information associated with the user and credential information associated with the external resource to which the user has requested access, wherein the credential information comprises a cryptographic key;

receiving authentication input from the user;

determining that the authentication input from the user matches the authentication information associated with the user included in the at least one record stored on the first device;

retrieving at least a portion of the credential information from the at least one record stored on the first device;

facilitating access of the user to the external resource at least in part by transmitting, on behalf of the user, from the first device, output based at least in part on the at least portion of the credential information retrieved from the at least one record, wherein the user of the first device is granted access to the external resource based at least in part on the output transmitted from the first device on behalf of the user; and

based at least in part on the first device and a second device being in a shared MAC address range, initiating a backup, to the second device, of at least a portion of the at least one record.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2023
From: CARBYNE LLC
To: CARBYNE BIOMETRICS, LLC
Reel/Frame 063049/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2022
From: RIGHTQUESTION, LLC
To: CARBYNE LLC
Reel/Frame 062191/0638 →
Continuity (10)
Continuation 17123018 · Dec 15, 2020
Continuation In Part 17027481 · Sep 21, 2020
Continuation 16773767 · Jan 27, 2020
Continuation 16563715 · Sep 6, 2019
Continuation 16273797 · Feb 12, 2019
Continuation 15042636 · Feb 12, 2016
Continuation 13706254 · Dec 5, 2012
Provisional Application 61587387 · Jan 17, 2012
Provisional Application 61569112 · Dec 9, 2011
Related Publication 20220342959A1 · Oct 27, 2022
Cited By (2)
US 12,363,093 US 12,598,190